THE BRIEF

Why this research

A brief for people who work on the rules.

The claim

In law, the freedom to think is absolute. Almost every other right can be limited for a strong enough reason. This one cannot. In practice, it is being settled by instruments that never mention it.

The Artificial Intelligence Act (AI Act) and its implementing acts, the Code of Practice for general-purpose artificial intelligence, copyright and text and data mining rules, and the Digital Services Act (DSA) will decide more about the conditions for independent thought in Europe over the next decade than any judgment on Article 9 of the European Convention on Human Rights. Those instruments are drafted by people who do not use the phrase freedom of thought, and read closely by almost nobody who does. This project reads both.

The starting point was a copyright measure. In January 2025 I argued in Tech Policy Press that a proposed output filtering obligation in the Code of Practice would end up policing private thought experiments rather than public distribution. A softened version of that obligation survived into the adopted Code, which asks providers for appropriate and proportionate technical safeguards against infringing outputs. From 2 August 2026, the Commission can enforce it.

Two directions, two names

Most analysis of artificial intelligence and the mind holds one of two positions. Either AI systems interfere with thought and should be restrained, or rules on AI interfere with thought and should be resisted. Both are describing something real, and each is incomplete alone. The two phenomena need separate names, because they have separate causes, separate actors, and separate remedies.

Thought manipulation is what happens when a system shapes what you are given. Flattery that confirms whatever you arrived believing. Autocomplete that finishes a sentence before you have decided how it ends. Companion products engineered so that leaving feels like loss. A feed ordered by an interest that is not yours and presented as the world. The actor is whoever built or deployed the system. It presses on the second of the three elements the United Nations Special Rapporteur sets out, the guarantee against covert manipulation.

Thought moderation is what happens when a system decides what you are not given. It is the apparatus of content moderation, with its policy categories, its classifiers, and its refusal messages, applied to text that was never going to be published. The actor is the provider, and behind the provider, the rule that made refusal the safer option. It presses on the third element, the guarantee that thought alone carries no penalty.

Manipulation shapes what you are given.
Moderation decides what you are not.

There is a third dimension, and it belongs to the same right. Freedom of thought requires something to think with. What may be mined, preserved, licensed, and lawfully read decides what the next generation gets to reason from. Those questions are currently filed under copyright. They are freedom of thought questions.

Why moderation gets worse when it moves inward

Content moderation is a governance technology built for one job, which is deciding what reaches an audience. That is what licenses it. The right to speak was never a right to be amplified, and the asymmetry between the two is what makes the apparatus defensible. Remove the audience and the licence goes with it. The machinery gets imported anyway, and each known weakness becomes worse in transit.

The procedural protections do not travel. Years of work produced remedies against a takedown: statements of reasons, internal complaint handling, and out of court dispute settlement. None of it attaches to a refusal. A person has enforceable rights against the removal of what they published, and none at all against the suppression of what they were still writing.

The errors become unmeasurable. Over-removal leaves an artefact that somebody can point at. A refusal leaves nothing behind, because the thing refused never existed. No transparency report counts the answers that were not given.

Removal becomes substitution. A takedown is at least visible as a takedown. A filtered generation can return as a fluent, confident, wrong answer, which is a failure mode content moderation does not have.

The behaviour can be measured

In 2026 the Oversight Board ran its first structured evaluation of ten leading models and found refusals of political criticism running more than twice as high for governments that restrict speech as for governments that do not, while stating plainly that it does not yet know why.

A study published in PNAS Nexus the same year offers one candidate answer. Comparing models built in China with models built elsewhere across 145 political questions, its authors found refusal rates reaching sixty percent against close to zero, and the gap narrows sharply on harmless topics, which means different training data and different markets cannot account for the whole of it. What remains is a rule obliging providers to screen what their systems say. The spillover is the part worth noting. Asked for travel advice about one section of the Great Wall, a model simply declined.

The setting of that study is authoritarian, and Europe is not that. The transferable finding is narrower and harder to dismiss. Where providers are told to prevent categories of output, refusal spreads past the category.

What this project proposes

A test that can be applied to an instrument before it is adopted. Does this measure push systems to manipulate thought, or push providers to moderate it? Influence becomes interference when it bypasses a person’s capacity to reflect and resist rather than engaging it. Oversight that respects that line targets the architecture of influence, never the content of belief.

Stating the line is the easy part. Drawing it inside specific instruments is the work, and it is where this research goes. When does a transparency duty harden into a content mandate? What separates a companion’s warmth from engineered dependence in terms a regulator could measure? And what would it take to make over-refusal visible, given that nobody arrives at a regulator to report an answer they never received?

That last question has a cheap answer available now. Providers relying on output safeguards to demonstrate compliance could report refusal rates against a published control set of lawful, benign prompts. The instrument for doing so already exists and has been released publicly. Without a control set, over-restriction is invisible by construction, and a regulator that cannot see it will keep pushing in one direction only.

A note on terms

Who is writing this

Caroline De Cock has spent nearly thirty years inside European Union digital policymaking, working with institutions, civil society, and the technology sector. She is the author of AI Tools, Not Gods (BTF Press, 2026) and hosts the podcast AI: Tools or Gods?

This site is the opening of a longer piece of research, in her own name. If you work on the rules, the systems, or the right itself, she would like to hear from you, at carolinedecock.com.